Fusion Border SDN
Fusion Border SDN
Fusion Border SDN
Cisco SD-Access
Connecting to the Data Center, Firewall,
WAN and More !
Satish Kondalam
Technical Marketing Engineer
Session Abstract
This session introduces best practices for Design and Deployment when connecting to the
external world/networks from the fabric along with decision criteria for different deployment
models. The Cisco SD-Access Border node is responsible for connecting fabric to rest of the
world and hence we will focus on the different connectivity models that will be provided by the
border node and discuss the various designs along with scale and platform support. We will
also include an demo for every design and deployment model that we will discuss during the
presentation. This session focuses on how the Cisco SD-Access architecture connects your
campus to the following and how we enforce end-to-end policy between them : Integration
between Cisco SD-Access ( Campus network) to Cisco SD-WAN (Viptela) Data center ( ACI
and Non ACI) Internet Connecting to remote branches Cloud across a WAN /Metro network.
Layer 4 to 7 Service integration for the fabric network , etc.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Sessions are available Online @ CiscoLive.com
Tuesday (Jan 29) Wednesday (Jan 30) Thursday (Jan 31) Friday (Feb 01)
08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00
BRKCLD-2412 BRKCRS-3811
Cross-Domain Policy SD-Access Policy
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Session Goals
• This session assumes that there is a basic understanding
of Cisco SD-Access and is recommended that you
attend BRKCRS-2810 before this.
• To provide an understanding of the Cisco SD-Access
Border architecture and the external Integration between
Cisco SD-Access (Campus network) to SD-WAN
(Viptela network), Data center (ACI and Non ACI),
Internet Connecting to remote branches and Cloud
across a WAN /Metro network, Layer 4 to 7 Service
integration for the fabric network.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
• Introduction to Cisco SD-Access
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Cisco SD-Access
Fabric Terminology
Encapsulation
Hosts
(End-Points)
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Cisco SD-Access Fabric
Control-Plane Nodes – A Closer Look
B B
• Host Database supports multiple types of Endpoint
ID lookup types (IPv4, IPv6 or MAC)
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Cisco SD-Access Fabric
Edge Nodes – A Closer Look
Edge Node provides first-hop services for Users / Devices connected to a Fabric
B B
• Register specific Endpoint ID info (e.g. /32 or /128)
with the Control-Plane Node(s)
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Cisco SD-Access Fabric
Border Nodes
Border Node is an Entry & Exit point for data traffic going Into & Out of a Fabric
B B
• Rest of Company/Internal Border Used for
“Known” Routes inside your company
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Cisco SD-Access Fabric
Border Nodes – Rest of Company/Internal
B B
• Exports all internal IP Pools to outside (as
aggregate), using a traditional IP routing protocol(s).
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Cisco SD-Access Fabric
Border Nodes – Forwarding from Fabric to External Domain
3 EID-prefix: 192.1.1.0/24
Path Preference
Mapping Locator-set: Controlled
Entry 2.1.1.1, priority: 1, weight: 100 (D1) by Destination Site
192.1.1.0/24
Border 5.1.1.1
Control Plane
5 2.1.1.1
nodes
SDA Fabric
4
1.1.1.1 2.1.1.1
10.1.1.1 192.1.1.1
1.1.1.1 Edge 1.1.2.1 1.1.3.1 Edge 1.1.4.1
2
10.1.1.1 192.1.1.1
1 S
DNS Entry: Campus
Campus
10.1.1.0/24 10.3.0.0/24 Bldg 2
D.abc.com A 192.1.1.1 Bldg 1
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Cisco SD-Access Fabric
Border Nodes – Forwarding from External to Fabric Domain
1
Routing Entry: 3 EID-prefix: 10.1.1.1/32
Send traffic to exit point of Path Preference
Mapping Locator-set: Controlled
domain(Internal Border)
Entry 1.1.1.1, priority: 1, weight: 100 (D1) by Destination Site
192.1.1.0/24
Border 5.1.1.1
Control Plane
2 2.1.1.1
nodes
4 SDA Fabric
2.1.1.1 1.1.1.1
192.1.1.1 10.1.1.1
1.1.1.1 Edge 1.1.2.1 1.1.3.1 Edge 1.1.4.1
5
192.1.1.1 10.1.1.1
D
Campus
Campus
10.1.1.0/24 10.3.0.0/24 Bldg 2
Bldg 1
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Cisco SD-Access Fabric
Border Nodes – Outside World/External
B B
• Exports all internal IP Pools outside (as aggregate)
into traditional IP routing protocol(s).
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Cisco SD-Access Fabric
Border Nodes – Forwarding from Fabric to External Domain
2 EID-Prefix: Not found , map-cache miss
Mapping Locator-Set: ( use-petr)
Entry 3.1.1.1, priority: 1, weight: 100 (D1)
INTERNET
193.3.0.0/24 D
4
Border
10.2.0.1 193.3.0.1
3.1.1.1
5.1.1.1
Control Plane
nodes
3 5.2.2.2
SDA Fabric
1.1.2.1 3.1.1.1
10.2.0.1 193.3.0.1
1
10.2.0.1 193.3.0.1
Campus S Campus
Bldg 1 10.2.0.0/24 10.3.0.0/24 Bldg 2
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Cisco SD-Access Fabric
Border Nodes – Anywhere/ Internal + External Border
Anywhere/ Internal + External Border is a “One all exit point” for any known
and unknown destinations
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Cisco SD-Access Fabric
Virtual Network– A Closer Look
Virtual Network maintains a separate Routing & Switching table for each instance
B B
• Nodes add a VNID to the Fabric encapsulation
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Large and Medium
Enterprise Network Design
Traditional Network
Design
Cisco SD-Access Fabric
3-Tier Enterprise Network Design – Traditional Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
Guest
WLCs
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Campus
Core WAN WAN HR/MC • ASR1K
Edge • ISR4K
Distribution
Nodes Data Center • N9K – NX-OS
• N7K - NX-OS
• N9K - ACI
Access
Nodes Security • ISE 2.3
• ASA 55xx
Large
Hybrid
Small • Windows AD
Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Cisco SD-Access Fabric
Large Enterprise Network Design – Traditional Network
Role Platform
Traditional VXLAN/ACI
DC Fabric Access Node • Cat3K/9300
• Cat4K/9400
Internet Edge
Collapsed Core • Cat6K/9500
Guest
WLCs
• N7K
Internet
Centralized • 5520
WLC • 3504
• x800 APs
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Cisco SD-Access
Network Design
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Fusion Router WAN HR/MC • ASR1K
WAN
Edge • ISR4K
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Fusion Router WAN HR/MC • ASR1K
WAN
Edge • ISR4K
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Fusion Router WAN HR/MC • ASR1K
WAN
Edge • ISR4K
Border
Data Center • N9K – NX-OS
• N7K - NX-OS
• N9K - ACI
Access
Nodes
Security • ISE 2.3
• ASA 55xx
Large
Hybrid
Small • Windows AD
Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Fusion Router WAN HR/MC • ASR1K
WAN
Border • ISR4K
Border
Data Center • N9K – NX-OS
• N7K - NX-OS
• N9K - ACI
Access
Nodes
Security • ISE 2.3
• ASA 55xx
Large
Hybrid
Small • Windows AD
Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Guest Access Node • Cat3K/9300
Border • Cat4K/9400
Distribution • Cat3K/9300
Node • Cat4K/9500
• Cat6K/9500
Internet Edge Internet
Core Node • Cat6K/9500
• NK7K
Centralized • ASR1K-HX
WLC
OTT
Centralized • 8540
WAN
Shared Services
WLC • 5520
• x800 APs
Fusion Router WAN HR/MC • ASR1K
WAN
Border • ISR4K
Border
Data Center • N9K – NX-OS
• N7K - NX-OS
• N9K - ACI
Access
Nodes
Security • ISE 2.3
• ASA 55xx
Large
Hybrid
Small • Windows AD
Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Border Connectivity
Models
Connectivity to external
networks in the
traditional design
Cisco SD-Access Fabric
Large Enterprise Network Design – Traditional Network
Traditional VXLAN/ACI
Data Center routes are advertised to the Campus Core
DC Fabric 1 via the DC Edge switch via BGP/IGP. Campus core
Internet Edge imports those routes into enterprise network.
Guest
WLCs
Internet
Centralized
WLC
OTT
Shared Services
WAN
Collapsed
Core WAN
Edge
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Cisco SD-Access Fabric
Large Enterprise Network Design – Traditional Network
Traditional VXLAN/ACI Default route for internet is advertised to the Campus
DC Fabric 2 Core via the Internet Firewall. The campus core in return
Internet Edge advertises the route to the enterprise network.
Guest
WLCs
Internet
Centralized
WLC
OTT
Shared Services
WAN
Collapsed
Core WAN
Edge
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Cisco SD-Access Fabric
Large Enterprise Network Design – Traditional Network
Traditional VXLAN/ACI Wan routes are advertised to the Campus Core via the
DC Fabric 3 Wan Edge router via BGP/IGP. Campus core imports
Internet Edge those routes into enterprise network.
Guest
WLCs
Internet
Centralized
WLC
OTT
Shared Services
WAN
Collapsed
Core WAN
Edge
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Cisco SD-Access Fabric
Large Enterprise Network Design – Traditional Network
Traditional VXLAN/ACI Guest Anchor WLC in the DMZ is responsible for guest
DC Fabric 4 wireless traffic since the traffic from the enterprise
Internet Edge network is directly anchored to it.
Guest
WLCs
Internet
Centralized
WLC
OTT
Shared Services
WAN
Collapsed
Core WAN
Edge
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Connectivity to external
networks in the Cisco
SD-Access design
using the Border Node
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric Data Center and Internet Border needs to be a
1 Anywhere/ Internal + External Border as it has to
import the DC routes into the fabric through the fusion
router.
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Edge
FABRIC DC &
Internet C
Border
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric Data Center and Internet Border needs to be a
2 Anywhere/ Internal + External Border as it also is the
default exit point out of the fabric aka “ Default route”.
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Edge
FABRIC DC &
Internet C
Border
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric Wan Border needs to be a Rest of the Company/
3 Internal Border as it has to import the WAN routes into
the fabric.
WAN
Centralized Border
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Edge
FABRIC C
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric There is a separate Guest Border in fabric for Guest VN
4 traffic only. This Border needs to be a Outside
Guest
Border world/External border as it is the default exit point out of
the fabric aka “ Default route” for the Guest VN.
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Edge
FABRIC C
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Why Internal (Rest of
Company) vs External
(Outside World) Border
Cisco SD-Access - Border Deployment
Why? Internal Traffic with External Borders
Edge Node
IP Network B
Edge Node
IP Network B
B
Traffic to internal domains will go
directly to the Internal Borders.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
For more details: cs.co/sda-compatibility-matrix
Cisco SD-Access Platforms
Fabric Control Plane
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
For more details: cs.co/sda-compatibility-matrix
Cisco SD-Access Platforms
Fabric Border Node
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
For more details: cs.co/sda-compatibility-matrix
Cisco SD-Access Platforms
Fabric Border Node
* EXTERNAL ONLY
• Catalyst 3650/3850 • Catalyst 6500/6800 • Nexus 7700 • ISR 4300/4400 • ASR 1000-X/HX
• 1/mG RJ45 • Sup2T/Sup6T • Sup2E • AppX (AX) • AppX (AX)
• 1/10G SFP • C6800 Cards • M3 Cards • 1/10G RJ45 • 1/10G ELC/EPA
• 1/10/40G NM Cards • C6880/6840-X • LAN1K9 + MPLS • 1/10G SFP • 40G ELC/EPA
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Cisco SD-Access - Border Deployment
Fabric Border Scale
n.a.
SGT/DGT Table 4K 8K 8K 8K 8K 30K 16K 62K
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric
Guest
Border
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Border
FABRIC DC &
Internet C
Border
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Cisco SD-Access - Border Deployment
Which Border to pick ?
Rest of Company (Internal) Connect to known part of the company like DC,
WAN etc.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Cisco SD-Access - Border Deployment
Fabric Border Support Matrix
N7K NO YES NO
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Cisco SD-Access – Border Deployment
How VNs work in SD-Access
provided by default
INFRA_VN
Devices (Underlay) GRT
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Connectivity to Known
Networks like DC &
WAN via the
Anywhere/Rest of
Company Border
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
WAN
Border
FABRIC DC &
Internet C
Border
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Border Deployment Options
Anywhere/Rest of Company for Shared Services and DC – VRF LITE
C
B
Shared Services
Data Center
B
Fusion Router
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Border Deployment Options
Anywhere/Rest of Company Border WAN Connectivity
LISP OMP/MP-BGP/IGP
CONTROL-PLANE
B C
WAN
B C
VXLAN MPLS/IP/IPSEC/DMVPN
DATA-PLANE
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Cisco SD-Access Fabric
Border Nodes – One Box vs. Two Box
OUT OUT
B
B
One Box Design IN
Two Box Design
IN
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Border Deployment Options
Anywhere/Rest of Company Border
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Border Deployment Options
Anywhere/Rest of Company Border
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Border Deployment Options
Anywhere/Rest of Company Border
SJC22
7 Select Remote AS
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Border Deployment Options
Shared Services (DHCP, AAA, etc) with Border
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Border Deployment Options
Shared Services (DHCP, AAA, etc.) with Border
C
Fusion Router
B B APIC
EM
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Border Deployment Options
Shared Services (DHCP, AAA, etc.) with Border ip vrf USERS
rd 1:4099
route-target export 1:4099
route-target import 1:4099
ip vrf DEFAULT_VN
1:4097
Global Routing Table should use a “Fusion” router with MP-BGP & rd 1:4098
route-target export 1:4098
VRF import/export.
route-target import 1:4098
route-target import 1:4097
SVI B
AF VRF B
ISIS BGP
GRT/VRF
B AF VRF A
AF IPv4
MP-BGP
Edge Node Border Node Fusion Router
VRF A External
SVI A Domain
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Border Deployment Options
Shared Services (DHCP, AAA, etc) with Border in dedicated VRF
5.1.1.1/32 C
Control-Plane Node
Host Pool 10 Edge Node 1 Border Node Fusion Router Shared Services in GRT
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Border Deployment Options
Shared Services (DHCP, AAA, etc) with Border in dedicated VRF
5.1.1.1/32 C
Control-Plane Node
Host Pool 10 Edge Node 1 Border Node Fusion Router Shared Services in VRF
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Border Deployment Options
Data Center Connectivity With Border – Traditional DC
CONTROL-PLANE
1 LISP BGP/IGP
Fusion Router
B B
S1 S2
DATA-PLANE
S3 S4
2
VXLAN+SGT VRF-LITE
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
S5
Border Deployment Options
Policy Options for Shared Services and Traditional Data Center
5.1.1.1/32 C
Control-Plane Node
Host Pool 10 Edge Node 1 Border Node Fusion Router Shared Services
Data Center
• Destination IP subnets are statically
mapped to SGT’s in ISE.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Border Deployment Options
Data Center Connectivity With Border – VXLAN/ACI Fabric
CONTROL-PLANE
1 LISP BGP/IGP
Fusion Router
B B ACI Fabric
Border Leaf’s
DATA-PLANE
2
VXLAN+SGT VRF-LITE
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Border Deployment Options
ip vrf CAMPUS
rd 1:4099
route-target export 1:4099
route-target import 1:4099
Border Leaf’s
• SD-Access Border merge the VRF’s A , B , C and so on to a common VRF D using a fusion router.
• The Common VRF D will connect to ACI VRF on the other side.
• We need access-lists/distribute lists on the fusion router to ensure that VRF A , B and C do not talk
to each other. This can also be achieved using VRF import and export maps.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Primer - ACI Fabric Integrated VXLAN Overlay
Decoupled Identity, Location and Policy
ACI Spine Nodes
ACI Fabric
VTEP VXLAN IP Payload
Forwarding within the Fabric is between VTEPs (ACI VXLAN tunnel endpoints) and leverages an
extended VXLAN header format referred to as the ACI VXLAN policy header
Any workload any where, Consistent Latency, Mapping of tenant MAC or Ip address to location is
performed by VTEP using distributed mapping database
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Primer :What is an L3Out?
L3Out is a logical construct defined to
allow L3 connectivity between the ACI
Fabric and the external network
One or more L3Outs can be defined for
L3Outs Container
each given tenant
L3 interfaces are used on specific ACI
Specific L3Out devices (named Border Leaf nodes) to
interconnect to the external routed network
L3 Interface on The external routed domain is modeled
Border Leaf Node with one (or more) External EPGs
Border Leaf (‘Networks’)
Node
A security policy (contract) is required to allow
External EPG communication between External and Internal
EPGs
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Cisco SD-Access SGTs Provisioned in ACI
ISE ACI
B B
EXT- EXT-
Cisco SD-Access Domain EPG1 EPG3
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
ACI EPGs Automatically Propagated into Cisco
SD-Access ACI
ISE
B B
VM1
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Hardware and Software recommendations
ACI Fabric
ACI Software ISE APIC
Hardware
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Cisco SD-Access SGT Info Used in ACI Policies
ISE
Cisco SD-Access ACI Policy Domain
Policy Domain
ISE Retrieves:
Controller Layer
ISE Exchanges:
Controller Layer
EPG Name:
SGT PCI EPG
Name: Auditor
EPG Binding = 10.1.100.52
SGT Binding = 10.1.10.220
PCI EPG
EPG Name = Auditor 10.1.100.52
Groups= 10.1.10.220
Network Layer
Network Layer
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Alternate Design Option
for fusion Router
Border Deployment Options
Firewall as fusion router
C
Firewall
B B APIC
EM
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Border Deployment Options
Firewall as fusion router
CONTROL-PLANE
1
LISP BGP/IGP
B B
Firewall
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Border Deployment Options
Firewall as fusion router
DATA-PLANE
2
VXLAN VRF-LITE
B B
Firewall
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Border Deployment Options
Firewall as fusion router
POLICY-PLANE
3
SGT in VXLAN SGT in-line Tagging
B B
Firewall
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Border Deployment Options
Firewall as fusion router ISE
POLICY-PLANE
3
SGT in VXLAN SGT in-line Tagging
Group Tags
C
SXP/PXGRID
B B
Firewall
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric
Internet
Centralized
WLC
OTT
WAN
Shared Services
Firewall
WAN
Guest Border
Border
FABRIC DC &
Internet C
Border
Access
Nodes
Large Small
Hybrid Hybrid
WAN Site WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
WAN Connectivity
with Rest of Company
/Internal Border
Border Deployment Options
WAN Connectivity with Border- WAN (MPLS/DMVPN)
C
B
WAN
B
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Border Design Options
WAN Connectivity with Border - Control Plane
CONTROL-PLANE
11
LISP MP-BGP/IGP
C
B
WAN
B
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Border Design Options
WAN Connectivity with Border
DATA-PLANE
- Data Plane
12
VXLAN IPSEC/IP/MPLS
C
B
WAN
B
12
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Border Design Options
WAN Connectivity with Border
POLICY-PLANE
- Policy Plane
13
SGT in VXLAN SGT in IPSEC/DMVPN
C
B
SD-WAN
B
12
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
C
Control Plane
Cisco
DNA-Center
B C B C
SD-Access SGT in data plane
SD-Access
Fabric Site B C B C Fabric Site
WAN
Border Border
1
LISP MP-BGP LISP CONTROL-PLANE
12
VXLAN SGT (16 bits) IPSec/DMVPN CMD-SGT (16 bits) VXLAN SGT (16 bits)
DATA-PLANE
Header VNID (24 bits) Header VNID (24 bits) Header VNID (24 bits)
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
C
Control Plane
Cisco
DNA-Center
B C B C
SD-Access SD-Access
Fabric Site B C B C Fabric Site
WAN
Border Border
1
LISP MP-BGP LISP CONTROL-PLANE
12
VXLAN SGT (16 bits) MPLS VXLAN SGT (16 bits)
DATA-PLANE
Header VNID (24 bits) Header Labels VRF (24 bits) Header VNID (24 bits)
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Connectivity to Un-
Known Networks like
Internet via the
Anywhere Border
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Guest
Border
Fusion Router
FABRIC DC &
Internet C
Border
Access
Nodes
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Border Deployment Options
Anywhere Border for Internet – VRF LITE
C
B
Internet
SDA Fabric
B
Fusion Router/
Firewall
VXLAN VRF-LITE IP
DATA-PLANE
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Small Enterprise
Network Design
Traditional Network
Design
Cisco SD-Access Fabric
Small Enterprise Network Design – Traditional Network
Role Platform
Traditional
DC VXLAN/
ACI Fabric
Access Node • Cat3K/9300
• Cat4K/9400
Internet Edge
Collapsed Core • Cat6K/9500
Guest
WLCs
• ISR4K (WAN)
Internet
Centralized • 3504
WLC • x800 APs
Access
Nodes
Small Small
Hybrid Internet
WAN Site WAN Site
Large
Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Cisco SD-Access
Network Design
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
FABRIC
Small Small
Hybrid Internet
WAN Site WAN Site
Access Large
Nodes Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
FABRIC C
Small Small
Hybrid Internet
WAN Site WAN Site
Access Large
Nodes Hybrid
WAN Site
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional
DC
VXLAN/ACI
Fabric Role Platform
Access Node • Cat3K/9300
• Cat4K/9400
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Cisco SD-Access Fabric
Large Enterprise Network Design – Cisco SD-Access Network
Traditional VXLAN/ACI
DC Fabric
1 The Border needs to be a Outside world/external
world border as there is only one exit point from the
fabric to all external domains.
Centralized
WLC
OTT
WAN
Shared Services
Fusion Router
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Cisco SD-Access - Border Deployment
Which Border to pick ?
Rest of Company (Internal) Connect to known part of the company like DC,
WAN etc.
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Border Deployment Options
Outside World/External Border
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Border Deployment Options
Outside World/External Border
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Border Deployment Options
Outside World/External Border
CORE
SJC22
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
DEMO TIME
Conclusion
Session Summary
Cisco SD-
Access
Fabric
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
For more details: cs.co/sda-compatibility-matrix
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
What to Do Next?
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Cisco SD-Access Resources
Related Sessions
Cisco SD-Access - 8H Technical Seminar - TECCRS-3810
• Monday, Jan 28 8:30 AM - 6:45 PM
Cisco SD-Access - Technology Deep Dive - BRKCRS-3810 Cisco SD-Access - Scaling to Hundreds of Sites - BRKCRS-2825
• Tuesday, Jan 29 2:30 PM - 4:00 PM • Wednesday, Jan 30 2:30 PM - 4:00 PM
Cisco SD-Access - Connecting Multiple Sites - BRKCRS-2815 Cisco SD-Access – Integrating Existing Network - BRKCRS-2812
• Wednesday, Jan 30 11:00 AM - 1:00 PM • Friday, Feb 01 11:30 AM - 1:30 PM
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Cisco SD-Access Resources
Would you like to know more?
cisco.com/go/dna
cisco.com/go/sdaccess cisco.com/go/dnacenter
• SD-Access At-A-Glance • Cisco DNA Center At-A-Glance
•
•
SD-Access Ordering Guide
SD-Access Solution Data Sheet
cisco.com/go/cvd •
•
Cisco DNA ROI Calculator
Cisco DNA Center Data Sheet
• SD-Access Solution White Paper • SD-Access Design Guide • Cisco DNA Center 'How To' Video Resources
• SD-Access Deployment Guide
• SD-Access Segmentation Guide
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Cisco Webex Teams
Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
cs.co/ciscolivebot#BRKCRS-2821
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
Complete your online
session survey
• Please complete your Online Session
Survey after each session
• Complete 4 Session Surveys & the Overall
Conference Survey (available from
Thursday) to receive your Cisco Live T-
shirt
• All surveys can be completed via the Cisco
Events Mobile App or the Communication
Stations
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Continue Your Education
BRKCRS-2821 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Thank you